League AuraReport a concern

Security

How League Aura protects league data

Role-based access

League workspaces use authenticated accounts and role-based server checks. Chairman, Vice Chairman, Finemaster, Accountant and manager permissions are enforced by the application API, not only by hidden buttons.

Private storage and secrets

Manager portraits are kept in private storage. Service-role keys, email keys and other secrets remain on the server and are not included in browser code.

Transport and browser protection

Production traffic uses HTTPS. League Aura applies strict transport, framing, content-type, referrer, permissions and content-security headers to reduce common browser attacks.

Data minimisation

League Aura does not require an FPL password. Public fantasy data is combined only with the optional profile, access and email details required to provide the service.

Monitoring and recovery

Platform administration tracks failed automations, email failures, stale data, analytics jobs and capacity thresholds. Security-sensitive changes and access problems are investigated using limited operational logs.

Your account

Use a unique password and protect the email or Google account used to sign in. League administrators should enable multi-factor authentication on their email accounts and on any connected development services.

Responsible disclosure

Do not access data that is not yours or disrupt the service. Report a suspected vulnerability privately through Support with the page, steps and impact. We will acknowledge legitimate reports and prioritise risks affecting account or cross-league access.